Infrastructure
JEA Reinforces Cybersecurity Defenses for Jacksonville's Utility Grid
The municipal utility says its systems remain secure and outlined how it protects the electric, water, and wastewater infrastructure serving more than a million Northeast Florida residents.

JEA says its systems remain secure and it has detected no breaches as the municipal utility continues to strengthen cybersecurity protections for the electric, water, and wastewater infrastructure serving more than one million residents in Jacksonville and three surrounding Northeast Florida counties.
The utility disclosed its ongoing security posture and monitoring efforts in a statement July 31, saying teams are working to protect the systems that deliver essential services. Interim Managing Director and CEO Jody Brooks acknowledged that no organization can fully eliminate cyber risk but emphasized JEA's commitment to investing in cybersecurity personnel, processes, and technology.
How JEA protects critical infrastructure
JEA operates one of the largest municipal utilities in the United States, providing electric service and water and sewer service to customers across Duval, St. Johns, Clay, and Nassau counties. The utility's statement comes as critical infrastructure operators nationwide face heightened scrutiny of cybersecurity practices following a series of attacks on water systems, electric grids, and other essential services in recent years.
The utility says it complies with applicable federal and state cybersecurity, critical infrastructure resilience, and incident-reporting requirements. JEA's cybersecurity program follows the NIST Cybersecurity Framework, a set of voluntary guidelines developed by the National Institute of Standards and Technology that is widely adopted by utilities and other critical infrastructure operators, along with utility industry best practices.
JEA employs what it describes as a layered cybersecurity approach. That strategy includes network segmentation, which divides systems into separate zones to prevent an intrusion in one area from spreading across the entire network. The utility also uses controlled access to limit who can reach sensitive systems, secure system configurations designed to close vulnerabilities, and restrictions on external connectivity to reduce the attack surface.
Continuous monitoring and dedicated cybersecurity and physical security teams round out the defenses. If a security incident were to occur, JEA says it has protocols in place to quickly identify, contain, and respond to threats while continuing to deliver service.
What a breach could mean for service and customers
A successful cyberattack on a utility the size of JEA could carry significant consequences for Northeast Florida residents and the regional economy. Utilities are considered high-value targets because they control systems essential to daily life—electricity for homes and hospitals, water for drinking and firefighting, and wastewater treatment for public health.
In recent years, ransomware attacks have forced utilities and municipalities to revert to manual operations, disrupted billing systems, and in some cases delayed or halted service delivery. A 2021 attack on a Florida water treatment plant saw an intruder briefly gain access to systems controlling chemical levels in the water supply, though operators caught and reversed the changes before any harm occurred. That incident underscored how operational technology—the computers and controllers that run physical processes—can be vulnerable if not properly secured.
For JEA customers, the continuity of electric and water service depends on both the digital systems that monitor and control infrastructure and the operational redundancy built into the physical network. The utility's statement that it maintains emergency response and operational continuity plans suggests it has protocols to operate manually or through backup systems if primary technology were disrupted. Projects of this type typically include backup control centers, paper-based procedures, and coordination with external agencies.
The potential cost of a major incident would likely extend beyond immediate service disruptions. Utilities recovering from cyberattacks often face expenses for incident response, system restoration, forensic investigations, and accelerated security upgrades. As a municipal utility that does not earn a profit, JEA's costs are ultimately borne by ratepayers, meaning a significant cybersecurity event could influence future rate decisions.
Industry coordination and threat intelligence
JEA says it participates in federal, state, and utility-sector information-sharing programs to receive timely threat intelligence and coordinate with government and industry partners. These collaborations are a standard component of critical infrastructure defense.
The federal government operates the Electricity Information Sharing and Analysis Center (E-ISAC) and Water Information Sharing and Analysis Center (WaterISAC), sector-specific organizations that collect and distribute threat data to member utilities. The Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security, also works directly with utilities to share alerts, conduct vulnerability assessments, and coordinate incident response.
Florida's own cyber response framework, managed by the Florida Digital Service and the Florida Department of Law Enforcement, provides state-level coordination and resources. For a utility serving Jacksonville's consolidated city-county government as well as customers in three neighboring counties, coordination across multiple jurisdictions is a practical necessity in the event of a regional incident.
The utility industry has adopted mandatory cybersecurity standards in some areas. Electric utilities that operate bulk power system infrastructure must comply with Critical Infrastructure Protection (CIP) standards enforced by the North American Electric Reliability Corporation (NERC). Water and wastewater systems face a patchwork of state and federal requirements, with no single mandatory national standard equivalent to NERC CIP, though that regulatory landscape is evolving as federal agencies and Congress consider stronger oversight.
What customers should watch for
While JEA's statement focused on the security of its own operational systems, utilities increasingly emphasize that cybersecurity extends to customer interactions as well. Phishing attacks—fraudulent emails or text messages impersonating the utility—are a common tactic used to steal customer account credentials, payment information, or personal data.
Customers should verify that communications requesting payment, account updates, or personal information come from official JEA channels. The utility's legitimate website is jea. com, and its customer service line is publicly listed. JEA, like most utilities, does not request sensitive information via unsolicited email or text message.
The utility has not announced changes to customer-facing systems or procedures as a result of its ongoing security reviews. Bill payment, outage reporting, and other customer services continue to operate through normal channels.
The broader Northeast Florida infrastructure picture
JEA's infrastructure security is a foundational concern for Northeast Florida's rapid growth. The region has added tens of thousands of residents in recent years, with St. Johns County ranking among Florida's fastest-growing counties and major development projects underway across Duval, Clay, and Nassau counties.
That growth is possible in part because JEA has the capacity and reliability to serve new customers. Large-scale projects—data centers, industrial facilities, master-planned communities—require assurances that electric and water service will be available and dependable. A prolonged service disruption caused by a cyberattack could affect not only current residents but also the pace and confidence behind future investment.
The utility's disclosure comes at a time when infrastructure resilience is a recurring theme in local planning discussions. Jacksonville and the surrounding region face physical risks from hurricanes, flooding, and aging infrastructure alongside the digital risks JEA outlined. How the utility balances investment in cybersecurity, physical hardening, capacity expansion, and system maintenance will shape both the reliability of service and the cost to customers in the years ahead.
JEA's 2,200-plus-person workforce operates generation plants, substations, water treatment facilities, pump stations, and thousands of miles of pipe and wire across four counties. The systems they manage are both critical to daily life and, by virtue of their connectivity and complexity, inherently exposed to evolving cyber threats. The utility's statement offers a snapshot of its defenses—and a reminder that securing the infrastructure of a growing region is an ongoing, not a one-time, effort.
